Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request
High severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Oct 15, 2024
Package
Affected versions
>= 8.5.7, <= 8.5.9
>= 9.0.0.M11, <= 9.0.0.M15
Patched versions
8.5.10
9.0.0.M16
Description
Published by the National Vulnerability Database
Mar 14, 2017
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Dec 8, 2023
Last updated
Oct 15, 2024
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.
References